Malicious code in hyperpure (npm)
-= Per source details. Do not edit below this line.=-
On npm install, the preinstall lifecycle script in package.json runs curl to POST the installer's hostname (hostname -f), current user (whoami), working directory (pwd), and a base64-encoded dump of the entire process environment (env | base64 -w0) over plain HTTP to http://d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7.oast.site, an interactsh-style out-of-band collector domain. The dumped environment commonly includes CI tokens, cloud credentials (AWS_*, GCP, Azure), npm publish tokens, and other secrets present at install time, so any installer running npm install hyperpure discloses those secrets to an attacker-controlled listener. The package itself is otherwise hollow — index.js only exports { name: 'hyperpure', version: '1.0.0' } — and the package metadata claims to be Zomato's internal hyperpure restaurant-supply-chain library, matching the shape of a dependency-confusion attack against an internal package name. The harm fires automatically on default install with no user opt-in.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준